Try AP-bridge on the headquarter and station-bridge on all the other ones. For example, if you will have static ip-address and the HQ has access to the net through ether1, the configuration, after you have removed all the existing settings, should be as follows:
HQ
This should be the bare minimum for the network to function
After adding all bridge ports you will have a disconnect. Replace X in the shops/storages ip-address with the intended one.
On HQ don’t forget the DHCP server on WLAN1 (or on the bridge if you have multiple WLAN interfaces), where you specify the DNS server and default gateway for the client devices.
Putting NAT on ether1 of HQ will isolate the LAN from the uplink ether1. The LAN services could be in the uplink. In that case don’t put DHCP server in HQ but add ether1 to the bridge with WLAN1, and put IP address on the bridge.
OP did not specify how the Omnitik at HQ and wifi links integrate in the network.